There are millions of business-critical .NET Framework assemblies with no source code. ProvenPort modernizes them to modern .NET — and is the only approach that proves the result behaves identically to the original.
Problem
.NET Framework powered enterprise software for two decades. Today it is legacy — no new features, mounting security and compliance pressure — yet enormous amounts of it survive only as compiled binaries: source lost, vendors vanished, authors moved on.
Reverse-engineering yields code that frequently won't rebuild — and even when it does, no one can vouch for it.
The modern runtime silently changed subtle behaviors. A "successful" port can be quietly, dangerously wrong.
These are payroll engines, trading libraries, medical and industrial components. "Probably fine" is not an acceptable migration standard.
So the binary stays frozen — accumulating risk — because the safe path doesn't exist. Until now.
Solution
We don't ask you to trust modernized code. We measure it: establish the original binary's exact behavior, reproduce the same conditions on modern .NET, and compare. Differences are reconciled with verified, behavior-preserving changes until the old and new builds agree.
The output isn't just a modern build.
It's a modern build with a proof.
Why now
.NET Framework is end-of-the-road; security, compliance, and talent scarcity are forcing migration decisions now.
AI collapses the cost of the long tail of edge cases — but only when wrapped in a system that can measure binaries and verify every change.
The hard part lives deep in .NET internals — exactly where general-purpose AI fails and few engineers can operate.
Defensibility
Conversion is a commodity. The defensible asset is the verified know-how that makes a port faithful — and the ability to prove it. Both grow with use.
A growing library of verified, behavior-preserving techniques, accumulated from real binaries — expensive to rebuild and widening with every engagement.
Every binary we process expands what the system can handle. The product gets more capable — and harder to copy — the more it runs.
Equivalence is established by measurement, turning "trust me" into an auditable result — the thing enterprises need to sign off a migration.
Two decades inside .NET binaries. This is not an advantage you assemble from a weekend prototype.
Traction
For each library we modernize the legacy binary, then run the library's own test suite against the modernized assembly. Third-party validation, not self-reported demos.
| Library | Framework | Domain | Tests passing | Status |
|---|---|---|---|---|
| Iced | net 4.5 | x86 / x64 encoder-decoder | 481,397 / 481,397 | validated |
| MathNet.Numerics | net 4.8 | Numerical computing | 20,908 / 20,908 | validated |
| NodaTime | net 4.5 | Date & time | 18,702 / 18,702 | validated |
| Humanizer | net 4.8 | Text & localization | 15,023 / 15,023 | validated |
| NUnit | net 4.6.2 | Test framework | 6,264 / 6,264 | validated |
| FakeItEasy | net 4.6.2 | Mocking / test fakes | 5,119 / 5,119 | validated |
| AutoFixture | net 4.5.2 | Test-data generation | 4,382 / 4,382 | validated |
| Markdig | net 4.6.2 | Markdown parser | 3,795 / 3,795 | validated |
| System.Reactive | net 4.7.2 | Reactive extensions (Rx) | 3,692 / 3,692 | validated |
| AngleSharp | net 4.6.2 | HTML / CSS DOM engine | 3,643 / 3,643 | validated |
| Newtonsoft.Json | net 4.5 | JSON serializer | 3,464 / 3,464 | validated |
| MimeKit | net 4.6.2 | MIME / email parsing | 2,429 / 2,429 | validated |
| Sentry | net 4.6.2 | Error reporting | 2,386 / 2,386 | validated |
| SSH.NET | net 4.6.2 | SSH / SFTP client | 2,310 / 2,310 | validated |
| DocumentFormat.OpenXml | net 4.6 | Office Open XML | 2,304 / 2,304 | validated |
| Polly | net 4.6.1 | Resilience (retry / breaker) | 1,895 / 1,895 | validated |
| Cronos | net 4.5 | Cron scheduling | 1,868 / 1,868 | validated |
| BouncyCastle.Cryptography | net 4.6.1 | Cryptography suite | 1,529 / 1,529 | validated |
| DotLiquid | net 4.5 | Liquid templating | 1,427 / 1,427 | validated |
| Nito.Comparers | net 4.6.1 | Comparer composition | 1,351 / 1,351 | validated |
| ExCSS | net 4.8 | CSS parser | 1,263 / 1,263 | validated |
| McMaster.Extensions.CommandLineUtils | net 4.7.2 | Command-line apps | 1,120 / 1,120 | validated |
| SauceControl.Blake2Fast | net 4.6 | BLAKE2 hashing | 1,102 / 1,102 | validated |
| Verify | net 4.6.2 | Snapshot testing | 1,071 / 1,071 | validated |
| CsvHelper | net 4.8 | CSV parsing | 1,058 / 1,058 | validated |
| MailKit | net 4.6.2 | IMAP / SMTP / POP3 | 1,052 / 1,052 | validated |
| Bogus | net 4.0 | Fake-data generation | 1,051 / 1,051 | validated |
| SmartFormat | net 4.6.2 | String templating | 1,021 / 1,021 | validated |
| TimeZoneNames | net 4.6.2 | Localized TZ names | 1,001 / 1,001 | validated |
| MessagePack | net 4.7.2 | MessagePack serializer | 997 / 997 | validated |
| YamlDotNet | net 4.7 | YAML serializer | 884 / 884 | validated |
| FluentValidation | net 4.6.1 | Validation | 813 / 813 | validated |
| Refit | net 4.6.2 | Typed REST client | 810 / 810 | validated |
| CommonMark | net 4.5 | Markdown (CommonMark) | 736 / 736 | validated |
| NCalc | net 4.6.2 | Expression evaluation | 718 / 718 | validated |
| CommandLineParser | net 4.6.1 | Command-line parsing | 684 / 684 | validated |
| Semver | net 4.5.2 | Semantic versioning | 665 / 665 | validated |
| QRCoder | net 4.0 | QR-code generation | 644 / 644 | validated |
| MoonSharp.Interpreter | net 4.5 | Lua scripting | 638 / 638 | validated |
| Colourful | net 4.5 | Color science | 579 / 579 | validated |
| Serilog | net 4.7 | Structured logging | 578 / 578 | validated |
| FileHelpers | net 4.5 | Delimited / fixed-width files | 558 / 558 | validated |
| Flurl | net 4.7.2 | HTTP / URL building | 542 / 542 | validated |
| ExcelDataReader | net 4.6.2 | Excel reading | 501 / 501 | validated |
| Stateless | net 4.6.2 | Workflow / state machines | 424 / 424 | validated |
| Jil | net 4.5 | Fast JSON serializer | 410 / 410 | validated |
| DiscUtils.Core | net 4.5 | Disk images / filesystems | 404 / 404 | validated |
| NodaMoney | net 4.5 | Money / currency | 391 / 391 | validated |
| Mono.Cecil | net 4.0 | IL metadata read / write | 353 / 353 | validated |
| ICSharpCode.SharpZipLib | net 4.5 | Compression / archives | 339 / 339 | validated |
| KellermanSoftware.Compare-NET-Objects | net 4.6 | Object-graph comparison | 322 / 322 | validated |
| Rationals | net 4.7 | Rational arithmetic | 317 / 317 | validated |
| Pipelines.Sockets.Unofficial | net 4.6.2 | Socket pipelines | 287 / 287 | validated |
| K4os.Compression.LZ4 | net 4.6.2 | LZ4 compression | 282 / 282 | validated |
| Lib.Harmony | net 4.5.2 | Runtime method patching | 276 / 276 | validated |
| EmailValidation | net 4.6.2 | Email validation | 269 / 269 | validated |
| DiffPlex | net 4.5 | Text diffing | 248 / 248 | validated |
| Ensure.That | net 4.6.2 | Guard clauses | 226 / 226 | validated |
| Utf8Json | net 4.5 | UTF-8 JSON serializer | 209 / 209 | validated |
| HtmlSanitizer | net 4.6.2 | HTML sanitization | 198 / 198 | validated |
| ObjectDumper | net 4.8 | Object-graph dump | 192 / 192 | validated |
| LiteDB | net 4.5 | Embedded database | 186 / 186 | validated |
| zxcvbn-core | net 4.6.1 | Password-strength | 169 / 169 | validated |
| MiniProfiler.Shared | net 4.7.2 | Application profiling | 125 / 125 | validated |
| FluentFTP | net 4.6.2 | FTP client | 121 / 121 | validated |
| JsonSubTypes | net 4.6 | JSON polymorphism | 120 / 120 | validated |
| Sprache | net 4.5 | Parser combinators | 117 / 117 | validated |
| Namotion.Reflection | net 4.6.2 | Reflection / XML docs | 116 / 116 | validated |
| Mono.TextTemplating | net 4.7.2 | T4 templating | 112 / 112 | validated |
| Enums.NET | net 4.6.1 | Enum utilities | 111 / 111 | validated |
| DotNet.Glob | net 4.5 | Glob matching | 110 / 110 | validated |
| GraphQL.Client | net 4.6.1 | GraphQL client | 110 / 110 | validated |
| prometheus-net | net 4.6.2 | Metrics / Prometheus | 108 / 108 | validated |
| TimeZoneConverter | net 4.6.2 | Timezone conversion | 101 / 101 | validated |
| JsonDiffPatch.Net | net 4.5 | JSON diff / patch | 93 / 93 | validated |
| LitJson | net 4.5 | JSON serializer | 93 / 93 | validated |
| OptimizedPriorityQueue | net 4.5 | Priority queues | 89 / 89 | validated |
| HtmlAgilityPack | net 4.5 | HTML parsing | 85 / 85 | validated |
| TinyMapper | net 4.0 | Object-to-object mapping | 81 / 81 | validated |
| Scrutor | net 4.6.2 | DI assembly scanning | 80 / 80 | validated |
| Scientist | net 4.5.1 | Refactoring experiments | 76 / 76 | validated |
| DiffEngine | net 4.6.2 | Diff-tool launching | 74 / 74 | validated |
| Optional | net 4.5 | Functional option type | 69 / 69 | validated |
| MarkdownSharp | net 4.0 | Markdown parser | 58 / 58 | validated |
| BCrypt.Net-Next | net 4.6.2 | Password hashing (bcrypt) | 53 / 53 | validated |
| K4os.Hash.xxHash | net 4.6.2 | xxHash hashing | 42 / 42 | validated |
| Cyotek.Drawing.BitmapFont | net 4.8 | Bitmap-font parsing | 39 / 39 | validated |
| FastMember | net 4.6.1 | Fast reflection | 38 / 38 | validated |
| Otp.NET | net 4.6.1 | OTP / 2FA (TOTP/HOTP) | 37 / 37 | validated |
| FuzzySharp | net 4.6.1 | Fuzzy string matching | 37 / 37 | validated |
| Hashids.net | net 4.5 | ID obfuscation | 33 / 33 | validated |
| NGettext | net 4.6 | gettext localization | 30 / 30 | validated |
| Fastenshtein | net 4.6.2 | String distance | 28 / 28 | validated |
| NeoSmart.Unicode | net 4.6.1 | Emoji / Unicode | 25 / 25 | validated |
| Pluralize.NET | net 4.6 | Pluralization | 19 / 19 | validated |
| System.IO.Abstractions | net 4.7.2 | Filesystem abstraction | 18 / 18 | validated |
| OneOf | net 4.5 | Discriminated unions | 11 / 11 | validated |
| ValueOf | net 4.8 | Value objects | 8 / 8 | validated |
| RandomDataGenerator.Net | net 4.5 | Random data | 6 / 6 | validated |
| Figgle | net 4.5.2 | FIGlet ASCII-art text | 4 / 4 | validated |
In one library, the modernized build initially diverged on a specific input — a genuine behavioral change introduced by the modern runtime, invisible at build time. ProvenPort detected it, pinpointed the cause, and restored the original behavior. That's the entire value proposition in a single case: a migration that doesn't just convert — it knows the behavior is identical.
A test suite only covers the inputs its authors imagined. ProvenPort verifies the behavior itself: on a library with 15,000+ passing tests, it independently surfaced behavioral changes the modern runtime introduced that those tests never exercised. "The tests are green" is necessary but not sufficient — "we measured that it behaves identically" is what actually lets you sign off the migration.
Market
Financial, healthcare, industrial, and government systems carrying source-less .NET Framework components into a modern stack — under audit and compliance scrutiny.
System integrators and acquirers who inherit undocumented binaries and need a defensible, evidence-backed path forward.
Migration is a board-level mandate with a hard deadline and no good options. ProvenPort is the option that comes with a receipt.
Author
Principal Engineer working on Microsoft IDEs and developer tools. Creator of Reflexil, the widely-used .NET IL assembly editor. Co-founder of DataGalaxy. Two decades operating in exactly the domain ProvenPort requires — IL, decompilation, debuggers, and .NET runtime internals.
ProvenPort's advantage is not a clever prompt; it is accumulated, verifiable engineering in a domain most teams cannot enter.
The ask
We're partnering with a small number of organizations that have source-less .NET Framework binaries on the critical path to modernization. You bring a real binary and its acceptance criteria; we deliver a modern build with a proof — and shape the product around your evidence requirements.
Become a design partner →hello@provenport.ai